Combofix found an infection

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by clisna, Apr 11, 2014.

  1. clisna

    clisna Private E-2

    Hello, combofix found an infection and I don't know what it is. Can someone please tell me? I am really worried. I attached the logs. Thanks
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  3. clisna

    clisna Private E-2

    Ok I ran all the scan and the Read & Run me First. I hope there is nothing. Since this computer was not new when I bought it is it possible to check for hardware like keyloggers? And can you tell me what the combofix infection was exactly and how it acted on my computer? Thanks
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Impossible to say, all I know is that whatever it was infected a legitimate file, but that CF replaced it from a backup copy on your machine.



    Re run Hitman and have it remove what it finds.


    Delete this:
    • C:\Users\HP\AppData\Local\Web Freer


    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Now describe how the machine is running please. :)
     
  5. clisna

    clisna Private E-2

    Hello, thanks for your help. I cannot run hitman pro to delete the file cause the trial has expired. I ran the JRT and I attached the logs. I also used the combofix again for a scan and it found another infection. I really don't know what is happening. Either combofix is not good or there is something/someone infecting my machine on purpose. It hasn't been 3 days since last combofix scan and yet another infection. Could it be a rootkit or something? I am really worried right now. I attached the combofix logs also
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    [​IMG] For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options.

    To enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.

    To enter System Recovery Options by using Windows installation disc:

    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.
    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
    • Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this log to your next reply. (How to attach)
     
  7. clisna

    clisna Private E-2

    Hello, I ran the tool and attached the logs. Thanks.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  9. clisna

    clisna Private E-2

    Hello, I did the scan but nothing was found. I really don't understand. Maybe I should just format and re-install windows
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What made you run Combofix in the first place? (Curious) Also...WHERE did you download your copy of Combofix from?

    Run it again now and attach the resulting log. (But first... download a fresh copy from here http://majorgeeks.com/Combofix_d6402.html and let it overwrite the old. Reinstalling Windows is certainly an option, but would you not prefer that we tried here some more first?
     
    Last edited: Apr 14, 2014
  11. clisna

    clisna Private E-2

    Hello, I run combofix when I feel that my computer is not acting quite right. I got the copy from your website; sometimes I take it at bleeping computer also. So I ran the tool and nothing was found this time. Very weird!!!
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Surf around a day or two and then come back and let me know how it's running.
     
  13. clisna

    clisna Private E-2

    Hello, I'll do that but the computer is still running slow. I have a question: Is there a way to know if some kind of hardware keylogger is installed also? Maybe I should go to the hardware section but my shift buttons randomly stop working each time at system boot and sometimes when I am typing. I am going to open my laptop. Can you tell me what to look for (hardware that are not suppose to be there)? It will be deeply appreciated. Thanks
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am not seeing any signs of a software keylogger. You can ask about hardware keyloggers in the hardware forum if you like. But otherwise, pop back here in a couple days.

    Do not keep running combofix though, it's a double edged tool, and unfortunately can cause alot of damage in the wrong hands. When you post back here, I will probably have you run it then to see if it finds any more infected files.
     
  15. clisna

    clisna Private E-2

    Hello, the computer is not better. I really think there is something maybe undetectable. Last time I wanted to update Java and when it was installing an error occurred telling me that it could not be installed and when I press OK I get the message that Java has successfully installed. Same thing for a windows update: the windows update icon appears in the down right corner and when I open it to install it an error occurred again, I press OK and when I go to "check for updates" I could not find it and when I go to update history it's there. All that in the last couple of days. It happened to me also with an itunes update but that was a month ago. So I don't know what to do next. But I have a question: Do you think that Mac computers are safer that windows? Not in term of how many virus are out there but about the operation system and how hackable it is if someone is using the same wifi network as me for example. Thanks
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Give Combofix another run. Attach the log.
    Then I may have you run through the entire R&R again and also attach all of those requested logs. If I am NOT seeing any malware after that, and/or Combofix is no longer detecting infected files, then you will have to post in the software forum then about any non malware related subject.
     
  17. clisna

    clisna Private E-2

    Hello, I ran combofix and it found some things and deleted the. I don't know what they are but combofix did not say if they were infections or not. Now I am pretty sure there is some kind of rootkit or something. But I am afraid it will come back even if I reformat and reinstall windows. I have read that rootkits can come back even after wiping the hard drive. I don't know how it's possible but that is really scary stuff.

    So are Macs more secure than windows? Can you answer that if you can? Thanks
     

    Attached Files:

  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    never used a mac before in my life...

    Mac vs PC

    I don't know what is going on with your computer. I'm pretty sure it is not a rootkit. I am going to have a word with Chaslang, and get back to you with a response as soon as I can. Hang in there.

    In the mean time, please run this online scan and see if it finds anything. It will probably take a while to run so go off and do something for a bit. :)


    Run this and attach the results.

    Using ESET's Online Scanner
     
  19. clisna

    clisna Private E-2

    Hello, here is the ESET online scan. I don't understand what it found.
     

    Attached Files:

  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    How is the machine bahaving currently? ESET didn't find anything of great significance...
     
  21. clisna

    clisna Private E-2

    Hello, the computer is the same: very slow.
    I know that I am not good at computer and I just know how to use them but is there a possibility it might be a BIOS or RAM rootkit? I've been reading a lot online to determine what it is and I read that it's the worse infection. I don't really know. I even removed the CMOS battery yesterday just to be sure:confused I found the info on this website: http://www.technibble.com/rootkits-that-survive-hd-reformatting/.
     
  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What is inside of this folder? Anything?

    • C:\Windows\System32\%LOCALAPPDATA%
     
  23. clisna

    clisna Private E-2

    Hello, it is not a valid path. I copy and paste it and I get the following message:
    "Windows can't find 'C:\Windows\System32\%LOCALAPPDATA%'. Check the spelling and try again."
     
  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.

    Code:
    :Files
    c:\windows\system32\%LOCALAPPDATA%
    C:\Program Files\Enigma Software Group
    C:\fywa.odt
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into a text file to ATTACH into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  25. clisna

    clisna Private E-2

    Hello, sorry for the delay. When I copied and paste the command lines and pressed the "MoveIt!" button for OTM I got the following message: Windows has encountered a critical problem and will restart automatically in one minute. Please save your work... So the computer restarted and OTM generated a log that I attached.
     

    Attached Files:

  26. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Run Combofix just one more time and attach the resulting log.
    Also explain how things are running at this point.
     
  27. clisna

    clisna Private E-2

    Hello, I attached the combofix log. It did not find nothing. The computer is still slow and uses a lot of CPU.
     

    Attached Files:

  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    For Windows 7 you do not have enough RAM installed for things to be "smooth sailing" :( You have 1GB available and that's the absolute minimum for this OS. You should have about 4GB in there. No wonder you are running so slowly.

    You may want to take a look at this: http://windows.microsoft.com/en-GB/windows7/products/features/readyboost It might help whilst you wait for extra memory.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Press and hold the Windows key [​IMG] and then press the letter R on your keyboard. This opens the Run dialog box.
      • Copy and paste the below into the Run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    8. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    9. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds